Lexopti

Data Processing Agreement

Last updated : Juin 2026

This is an informal translation provided for convenience. Only the French version is legally binding. French version.

Annex to the Terms of Service regarding personal data processing (GDPR Article 28).

1. Preamble and Party Qualifications

1.1 This data processing annex (the "DPA Annex") sets forth the conditions under which LexOpti, acting as data processor within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR"), processes personal data on behalf of the User, the data controller. It formalizes the parties' commitments in accordance with Article 28, paragraphs 3 and 4, of the GDPR and French Law No. 78-17 of January 6, 1978.

1.2 The DPA Annex is part of the standard contractual clauses adopted by the European Commission in its Implementing Decision (EU) 2021/915 of June 4, 2021. Implementing Decision (EU) 2021/914 regarding transfers to third countries applies where applicable under the conditions set forth in Article 7.

1.3 The DPA Annex forms an integral part of the Terms of Service and prevails in case of conflict therewith.

1.4 The User acts as data controller for data relating to persons subject to verification as part of their AML/CFT due diligence obligations. When the User themselves acts as a processor on behalf of a third-party data controller, they commit to obtaining the necessary authorizations, declaring LexOpti as a sub-processor, having concluded with that controller a contract compliant with Article 28 of the GDPR, transmitting instructions consistent with those received, and making this Annex available to them.

1.5 The User remains fully responsible to LexOpti for compliance with this Annex by any third-party data controller on whose behalf they may act. The User indemnifies LexOpti against any claim resulting from a breach of these obligations, without this indemnification being opposable to data subjects or limiting LexOpti's liability under Article 82 of the GDPR.

2. Scope

2.1 This Annex applies to the processing described in Annex A, which forms an integral part of this document along with Annex B.

2.2 Any modification to the Annexes is limited to updating the information they contain and may not contradict the standard contractual clauses or prejudice the rights of data subjects.

3. Documented Instructions

3.1 LexOpti processes personal data only on documented instructions from the User and for the purposes described in Annex A. The ToS and this Annex constitute the complete set of instructions; any processing beyond this scope requires prior written agreement.

3.2 If a legal obligation requires LexOpti to process data, it shall inform the User beforehand, unless legally prohibited.

3.3 LexOpti immediately notifies the User of any instruction it considers to be in violation of the GDPR or applicable data protection regulations.

4. Personnel and Confidentiality

4.1 Access to personal data is limited to LexOpti personnel strictly authorized for service delivery. Each employee has personal credentials and an access level defined according to the principle of least privilege.

4.2 All personnel with access to data are bound by a written confidentiality obligation, enforceable even after the end of their employment contract.

4.3 Employees are trained on personal data protection issues and AML/CFT compliance risks. Access is revoked immediately upon departure or change of position.

5. Security Measures

5.1 LexOpti implements appropriate technical and organizational measures in accordance with Article 32 of the GDPR, taking into account the state of the art, implementation costs, and the nature of the processing. These measures are detailed in Annex B and reviewed periodically.

5.2 When processing involves special categories of data within the meaning of Articles 9 and 10 of the GDPR, LexOpti implements enhanced safeguards: specific encryption at rest and in transit, access restricted to trained personnel, detailed operation logging, and retention limited to the strict minimum.

5.3 In the context of AML/CFT due diligence analyses, these enhanced safeguards apply particularly to data relating to politically exposed persons, asset freezing measures, and alerts that may reveal offenses.

5.4 LexOpti incorporates data protection by design and by default principles in accordance with Article 25 of the GDPR, particularly through interfaces for managing data subject rights, automatic purge mechanisms, and restrictive privacy settings by default.

6. Sub-processing

6.1 The User authorizes LexOpti to engage sub-processors for Service delivery. The list of sub-processors is available upon request at contact@lexopti.com.

6.2 LexOpti notifies any addition or replacement of a sub-processor at least thirty days before it takes effect. The User may object for a legitimate reason related to data protection within this period. In the absence of objection, the sub-processor is deemed accepted.

6.3 If no alternative is possible and the objection is maintained, either party may terminate the contract with thirty days' notice.

6.4 LexOpti concludes with each sub-processor a contract imposing data protection obligations equivalent to those of this Annex and remains fully responsible for their acts. The User may request disclosure of this contract.

6.5 Any sub-processor processing sensitive data within the meaning of Article 5.2 is subject to enhanced confidentiality clauses and the same safeguards provided therein.

7. International Transfers

7.1 All data is hosted within the European Union. Any transfer to a third country may only occur on documented instruction from the User or to satisfy a legal requirement applicable to LexOpti, in which case LexOpti shall inform the User beforehand unless legally prohibited.

7.2 When a sub-processor is established outside the European Economic Area, LexOpti ensures the implementation of a transfer mechanism compliant with Chapter V of the GDPR: European Commission adequacy decision, adherence to a recognized certification mechanism, standard contractual clauses adopted by Implementing Decision (EU) 2021/914, or binding corporate rules approved by a supervisory authority.

7.3 The User mandates LexOpti to conclude standard contractual clauses on their behalf when necessary.

7.4 Prior to any transfer to a third country not benefiting from an adequacy decision, LexOpti performs a transfer impact assessment in accordance with European Data Protection Board Recommendations 01/2020 and implements, if necessary, additional technical, contractual, or organizational measures ensuring a level of protection equivalent to that of the European Union.

8. Data Subject Rights

8.1 LexOpti assists the User in responding to data subject rights requests: access, rectification, erasure, restriction, portability, and objection. This assistance is provided under conditions allowing compliance with the one-month legal deadline.

8.2 When LexOpti receives a request directly from a data subject, it shall inform the User as soon as possible and shall not respond itself unless expressly authorized by the User.

8.3 LexOpti also contributes to the User's compliance with obligations relating to data accuracy and updating, as well as processing security within the meaning of Article 32 of the GDPR.

9. Audit, Documentation, and DPIA

9.1 LexOpti makes available to the User the information necessary to demonstrate compliance with this Annex and allows audits, including inspections, by the User or a mandated third-party auditor.

9.2 Audits are conducted with thirty days' notice, during business hours, limited to once per year unless requested by a supervisory authority or following a data breach. The third-party auditor is subject to a prior confidentiality commitment.

9.3 LexOpti may provide its certifications and independent audit reports in addition, without substituting for the User's audit right.

9.4 LexOpti assists the User in complying with their obligations under Articles 32 to 36 of the GDPR, particularly for conducting data protection impact assessments and prior consultation with the supervisory authority.

9.5 Assistance services exceeding LexOpti's legal obligations may be subject to additional billing after prior notification to the User.

10. Data Breaches

10.1 In case of a personal data breach within the meaning of Article 4(12) of the GDPR, LexOpti notifies the User as soon as possible, and no later than seventy-two hours after becoming aware of it. The contact point for notifications is the email address associated with the User's account, or failing that, contact@lexopti.com.

10.2 The initial notification includes the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and the measures taken or proposed to remedy it. The identity and contact details of the dedicated contact point are communicated in this notification.

10.3 Additional information is communicated progressively as it becomes available, including: detailed incident timeline (date and time of discovery, likely nature, identified attack vector, affected systems or data), remediation measures with deployment schedule, and recommendations for the User to minimize the consequences of the breach.

10.4 LexOpti documents any breach, including its effects and corrective measures applied. This documentation is made available to the User and the supervisory authority. LexOpti maintains an internal breach register of which the User may request disclosure, for breaches concerning them, within a maximum period of thirty days.

10.5 LexOpti cooperates with the User to help them fulfill their notification obligations to the CNIL in accordance with Article 33 of the GDPR and, where applicable, communication to data subjects in accordance with Article 34 of the GDPR.

11. Duration, Retention, and Data Fate

11.1 Processing is carried out for the duration of the contract. Specific retention periods are specified in Annex A.

11.2 Upon expiration or termination of the contract, the User has ninety days to request either the return of all data in a structured, commonly used, and machine-readable format, or their deletion accompanied by a certificate of destruction.

11.3 Failing instructions within this period, LexOpti retains data for the minimum period required by regulations applicable to the User, particularly five years from file closure or the end of business relations in accordance with Article L.561-12 of the French Monetary and Financial Code, then proceeds with permanent deletion.

11.4 During this retention period, LexOpti guarantees data confidentiality and restricts access to strictly necessary personnel. LexOpti may also retain certain data if required by law, only for the duration and purposes provided thereby.

12. Breach and Termination

12.1 In case of breach by LexOpti of its obligations under this Annex, the User may require it to suspend all processing until the situation is remedied or until contract termination.

12.2 The User may terminate the contract as of right if the suspension mentioned in 12.1 is not lifted within one month, if LexOpti commits a serious or repeated violation of this Annex, or if LexOpti fails to comply with an enforceable decision of a supervisory authority.

12.3 LexOpti may terminate the contract if, after warning the User that their instructions constitute a violation of applicable law, the User maintains their instructions.

13. Applicable Law and Jurisdiction

13.1 This Annex is governed by French law. For the standard contractual clauses incorporated herein, the parties agree to the application of French law in accordance with their clause 17.

13.2 When the User acts in the context of their professional activity, any dispute relating to the interpretation or execution of this Annex is subject to the exclusive jurisdiction of the Commercial Court of Nice or, failing that, the Judicial Court of Nice.

13.3 When the User is not acting in the context of their professional activity or falls within the category of non-professionals under the Consumer Code, the common law rules on territorial jurisdiction apply.

Annex A — Description of Processing

A.1 Data Subjects

The processing concerns the following categories:

  • Service users (administrators, employees) and their account data;
  • clients registered by the User as part of their due diligence obligations;
  • natural persons subject to verification: comparers, beneficial owners, legal representatives, identified politically exposed persons;
  • legal entities analyzed: companies, associations, entities subject to verification.

A.2 Categories of Data

Processed data includes:

  • Identification: surname, first name, date and place of birth, nationality, gender, marital status;
  • Contact: postal address, email address, phone number;
  • Professional identification: profession, organization, registration number (professional body, regulatory body), SIREN/SIRET;
  • Supporting documents: identity documents, proof of address and nationality transmitted by the User;
  • Connection and logging: IP address, User Agent, session identifiers, access timestamps, addresses of resources consulted;
  • AML/CFT due diligence: verification results (sanctions lists, asset freezing, politically exposed persons), media alerts, beneficial owner information, risk level;
  • Generated data: analysis reports, timestamped audit trails, verification history;
  • any other data transmitted by the User in the context of their use of the Service.

A.3 Purposes

LexOpti processes data on behalf of the User for the following purposes:

  • provision and operation of the AML/CFT compliance Service;
  • execution of due diligence analyses: verification against sanctions and asset freezing lists, identification of politically exposed persons, adverse information searches;
  • generation, retention, and provision of compliance reports and audit trails;
  • assistance to the User in complying with their professional and regulatory obligations;
  • Service security, error management, and access logging.

A.4 Nature of Operations

Operations performed include: collection, reception, recording, structuring, storage, encryption, consultation, querying external databases, analysis, verification, matching, transmission, restitution, and deletion of data, as well as any other processing necessary for Service provision.

A.5 Duration

Processing is carried out for the duration of the contract. Upon termination, data is retained in accordance with Article 11 of this Annex and, where applicable, for the minimum period provided by Article L.561-12 of the French Monetary and Financial Code (five years from file closure or the end of business relations).

Annex B — Technical and Organizational Measures

LexOpti implements the following measures in accordance with Article 32 of the GDPR, taking into account the state of the art, implementation costs, and the nature of the processing. Pseudonymization techniques are applied where appropriate to the processing. These measures are reviewed periodically and adapted to evolving risks.

B.1 Hosting and Infrastructure

All data is stored on servers located in the European Union. The infrastructure relies on certified data centers equipped with physical access controls, intrusion detection systems, and electrical and network redundancy devices. Network security is ensured through firewalls, environment segmentation, and access compartmentalization.

B.2 Encryption

Data is encrypted at rest and in transit according to industry-recognized standards. Encryption keys are managed securely with role separation. Communications between the User and the Service occur exclusively via secure connections (HTTPS/TLS).

B.3 Access Control

Data access is based on role-based control and the principle of least privilege. Each employee has personal credentials. Enhanced authentication, including two-factor authentication where the Service provides it, is offered to Users. Access is revoked immediately upon departure or change of position.

B.4 Logging and Monitoring

Data access and sensitive operations are subject to timestamped logging. Connection logs are retained for twelve months in accordance with legal obligations. Monitoring mechanisms detect abnormal behavior or unauthorized access attempts.

B.5 Backups and Continuity

Encrypted backups are performed regularly and stored on separate servers within the European Union. Restoration tests are conducted periodically. A business continuity and disaster recovery plan is maintained to ensure Service availability in case of a major incident.

B.6 Application Security

The Service is regularly updated including security patches. Vulnerabilities are tracked and corrected according to their criticality. Security tests are performed periodically to identify potential flaws.

B.7 Incident Management

Documented procedures govern security incident management and data breach notification.

B.8 Certifications

LexOpti commits to maintaining or obtaining recognized security certifications (ISO 27001, SOC 2 Type II) and communicating corresponding audit reports upon User request.

B.9 Review

Security measures are audited at least once per year and reviewed following any significant incident. Substantial modifications are communicated to the User.